Privacy Policy

Version 2.0 Effective Date: July 10, 2026

Introduction

This Privacy Policy explains how the TeachMetrics application (the "App"), self-hosted web software by CPE.io LLC, a Georgia limited liability company, doing business as TeachMetrics, handles your information. TeachMetrics is offered two ways: self-hosted, where you install and run the App on your own server, and managed hosting, where we run your instance of the App for you. By using the App or our website, you agree to this policy.

1. Data Collection and Processing

1.1 Data the App Processes

TeachMetrics connects to your Teachable school using your Teachable API key and Teachable webhooks. The following data is fetched from your Teachable account and stored in the App's own database:

  • Student Information: Student names, email addresses, enrollment dates, and progress data from your Teachable school
  • Course Information: Course names, pricing, and structure
  • Transaction Data: Revenue, refunds, and payment information from your Teachable school
  • Enrollment Data: Course enrollments, completion rates, and progress percentages
  • Analytics Data: Aggregated metrics calculated from the above data

Self-hosted: the App runs on your own server, and its database lives on infrastructure you control. Data flows directly between your server and Teachable. We do not receive, store, or have access to your Teachable data or your API key.

Managed hosting: we operate your instance of the App on infrastructure we manage. Your school's data is stored in a dedicated database for your instance, and we process it solely to provide the service to you. We do not share it with third parties for their own purposes or use it beyond operating and supporting your instance.

We do not sell personal data — yours or your students' — under either deployment model.

1.2 How the App Uses Your Data

  • To provide analytics and insights about your Teachable school
  • To generate reports on student progress, revenue, and course performance
  • To apply real-time webhook events for up-to-date analytics
  • To send email campaigns you compose, through the email (SMTP) provider you configure
  • To answer questions you ask through the App's optional AI features (see 1.4)

1.3 Real-Time Webhooks

Your TeachMetrics installation receives Teachable webhook events (such as new enrollments, completions, and transactions) directly from Teachable at your installation's own webhook URL. No third-party relay services are involved. Webhook payloads are stored in the App's database as part of its auditable record of your school's activity.

1.4 Optional AI Features

If you enable the App's AI features, your questions are answered from aggregate data only. The App sends the configured AI provider your question together with either a curated snapshot of aggregate school metrics or the results of a query that can only read the App's aggregate analytics views — counts, revenue totals, rates, and rollups labeled by course, month, country, coupon, and author. Individual student records — names, email addresses, and per-student activity — are never sent to an AI provider.

This is enforced by the App itself, not by the AI provider: AI-generated queries are validated against an allow-list of aggregate-only data views and run read-only, so the same protection applies regardless of which AI provider is configured. The App also shows you exactly what was sent alongside each AI answer. AI features are off until an AI provider is configured (your own provider account if self-hosted; the provider we configure if you purchase AI as a managed add-on).

If you self-host and modify the App — including its AI prompts, data views, or query safeguards — you are responsible for any data your modified installation sends to an AI provider. See our Terms of Service.

1.5 Our Website

teachmetrics.co is a static website that makes no third-party requests at all: no advertising or tracking cookies, no analytics scripts, and no external CDN assets (even fonts are served from our own domain) — so your visit here is not disclosed to any other company. If you contact us or purchase TeachMetrics, we collect the information you provide (such as your name and email address) to deliver the product, provide support, and manage your subscription. Payments are processed by our payment processor; we do not store your card details.

2. Data Storage and Security

2.1 Self-Hosted Architecture

TeachMetrics is built so your school data stays under your control:

  • Your Teachable data is stored in the App's own MySQL database — on your server (self-hosted) or in a dedicated database for your instance (managed)
  • Your Teachable API key and other secrets are encrypted at rest with AES-256-GCM; administrator passwords and API tokens are stored only as one-way bcrypt hashes
  • The App sets no advertising or tracking cookies — only a hardened sign-in session cookie and a theme preference
  • All connections to Teachable and to the App's dashboard use HTTPS
  • Self-hosted: no Teachable data is transmitted to or stored on our servers

2.2 Third-Party Services

The App interacts with the following services on your behalf:

  • Teachable API and webhooks: to fetch and receive your school data (using your API key)
  • Your SMTP provider: if you configure email campaigns, mail is sent through the provider you choose
  • Your AI provider: if you enable AI features (see 1.4)

3. Data Processing and Subprocessors

Self-Hosted

Data flows directly between your server and Teachable.com. We are not a processor of your school data and no subprocessors of ours are involved. Any services you connect (your web host, SMTP provider, AI provider) are your own vendors under your own agreements.

Managed Hosting

If we host your instance, we process your school data as described in the DPA below, using the following subprocessors:

  • Pair Networks: server infrastructure hosting your instance and its database
  • Wasabi: S3-compatible object storage holding encrypted backups of your instance's database

Each subprocessor is bound by appropriate data protection agreements.

4. Your Rights

You have the right to:

  • Access your data: View all data stored in the App at any time
  • Export your data: Export your analytics data as CSV; self-hosted operators also have full direct access to the App's MySQL database
  • Delete your data: Self-hosted, delete the App's database at any time; managed, request deletion of your instance and we will delete it
  • Revoke API access: Rotate or remove your Teachable API key at any time
  • Stop webhook delivery: Deactivate or remove the App's webhook URL in your Teachable admin console at any time — webhook events are sent by Teachable, so this control is always yours, independent of the App

5. Data Retention

  • Self-hosted: your data lives in your own database for as long as you keep it; we hold nothing to retain or delete.
  • Managed hosting: your instance's data is retained while your subscription is active. On termination, you may export your data; we delete the instance and its backups within 30 days of termination.
  • Purchase records: we retain billing and license records as required for tax and accounting purposes.

6. Changes to This Policy

We may update this privacy policy from time to time. We will notify you of any changes by:

  • Updating the Policy Version
  • Updating the "Effective Date"
  • Posting a notice in the App

7. Contact Us

If you have any questions about this privacy policy, please contact us at:

CPE.io LLC
DBA TeachMetrics
1063 Sheridan Park NE
Atlanta, GA 30324

8. Compliance

The App is designed to support your compliance with:

  • GDPR requirements
  • CCPA requirements
  • Other applicable privacy regulations

9. Data Processing Agreement (DPA)

We are committed to transparency in our data processing practices. If you self-host TeachMetrics, we do not process your school data and this DPA does not apply — you are the sole controller and host of your data. The following Data Processing Agreement (DPA) applies to managed hosting customers:

Data Processing Agreement (DPA) for TeachMetrics Managed Hosting

Definitions

  • "App Data" means all data processed by your managed TeachMetrics instance, including student information, course data, transaction records, and analytics.
  • "Applicable Data Protection Laws" means all laws and regulations relating to the processing and protection of personal data, including GDPR and CCPA.
  • "Services" means the managed TeachMetrics instance we operate for you.

Data Processing Details

  • Subject Matter: Processing of Teachable school data for the purpose of providing analytics and email services.
  • Duration: For as long as the customer's managed hosting subscription is active.
  • Nature and Purpose: To operate the customer's TeachMetrics instance — analytics, reporting, insights, and email campaigns for their Teachable school.
  • Types of Data Processed: Student information, course data, enrollment records, transaction data, and derived analytics.
  • Categories of Data Subjects: Teachable school owners (our customers) and their students (data subjects in Teachable).

Technical and Organizational Measures

  • Each managed instance runs with its own dedicated database, separated from other customers.
  • API keys and other secrets are encrypted at rest with AES-256-GCM.
  • All data in transit is protected with HTTPS/TLS.
  • Database backups are encrypted.
  • Administrative access to instances is restricted to what is necessary to operate and support the service.

Subprocessors

Subprocessors are limited to Pair Networks (server and database infrastructure) and Wasabi (S3-compatible storage of encrypted backups). Each subprocessor is bound by appropriate data protection agreements.

Data Subject Rights

Customers may access, export, or delete their data at any time via the App or by contacting us. For data subject requests from students in your Teachable school, please handle these through Teachable directly; we will assist with corresponding deletions from your instance on request.

Data Breach Notification

In the event of a data breach affecting your managed instance, we will notify you promptly in accordance with applicable laws via email and notices on our website.

Data Transfers

Managed instances are hosted on infrastructure in the United States. Your Teachable data is transferred between your instance and Teachable.com, and to no other party except the subprocessors listed above. If you are located outside the United States, you consent to your instance's data being transferred to, stored, and processed in the United States.

Data Retention

Instance data is retained while the subscription is active. Upon termination, the customer may export their data; we delete the instance and its backups within 30 days of termination.

Termination

Upon termination of managed hosting, you may export your data (or request a full database export to migrate to a self-hosted installation). After the deletion window, removal of your instance's data is permanent and irrevocable.

Contact Information

For DPA inquiries, please contact us by email at or by mail at: CPE.io LLC, DBA TeachMetrics, 1063 Sheridan Park NE, Atlanta, GA 30324

Governing Law

This DPA is governed by the laws of the State of Georgia, USA.

Changes to DPA

This DPA may be updated. Users will be notified of significant changes.